CVE-2024-50599
largeReflected XSS in Zimbra Collaboration Suite 8.8.15 webmail calendar endpoint
CVE-2024-50599 is a reflected Cross-Site Scripting (XSS) flaw (CWE-79) in one of the webmail calendar endpoints of Zimbra Collaboration Suite (ZCS) 8.8.15, caused by improper handling of user-supplied input that is reflected back into the HTML response. An attacker triggers it by getting a victim to click a crafted link to the calendar endpoint; the injected code is then reflected and executed in the victim's browser. Successful exploitation lets the attacker run script in the victim's webmail session context, with potential to steal session information or act as the user (CVSS 6.1 medium, user interaction required, scope changed). Organizations running ZCS 8.8.15, particularly those exposing webmail to the internet, are affected. The flaw is not yet in the CISA KEV catalog and no public proof-of-concept is known, but the 60.7% EPSS score (99th percentile) indicates a high probability of exploitation within 30 days.
What to do: Apply the latest 8.8.15 patch level published by Synacor in its security advisory, or migrate to a currently supported ZCS release, without delay given the elevated EPSS score. Restrict internet exposure of the webmail calendar endpoint where possible and review webmail access logs for anomalous requests to calendar URLs. Caution users against clicking untrusted links that point to their webmail domain, since reflected XSS requires user interaction.
| Synacor Zimbra Collaboration Suite (ZCS) | 8.8.15 (only version named in the advisory; webmail calendar endpoint) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject malicious code that is reflected back in the HTML response.
- Vendors
- synacor
- Products
- zimbra collaboration suite
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.